CVE-2024-53279

Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in file station functionality in Synology Router Manager (SRM) before 1.3.1-9346-10 allows remote authenticated users with administrator privileges to read or write specific files containing non-sensitive information and conduct limited denial-of-service attacks by injecting arbitrary web script or HTML.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:synology:router_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:-:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update1:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update2:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update3:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update4:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update5:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update6:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update7:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update8:*:*:*:*:*:*
cpe:2.3:o:synology:router_manager:1.3.1-9346:update9:*:*:*:*:*:*

History

No history.

Information

Published : 2024-12-09 04:15

Updated : 2025-08-04 19:08


NVD link : CVE-2024-53279

Mitre link : CVE-2024-53279

CVE.ORG link : CVE-2024-53279


JSON object : View

Products Affected

synology

  • router_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')